| CVE-2026-35325 | 8.8 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 115d ago |
| CVE-2026-35324 | 8.8 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 115d ago |
| CVE-2026-35322 | 8.8 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 115d ago |
| CVE-2026-35318 | 8.8 | — | — | — | oracle / webcenter sites | Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). | 115d ago |
| CVE-2026-35317 | 8.8 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 115d ago |
| CVE-2026-35315 | 8.8 | — | — | — | oracle / webcenter content | Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). | 115d ago |
| CVE-2026-35311 | 8.8 | — | — | — | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Core). | 115d ago |
| CVE-2026-35303 | 8.8 | — | — | — | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | 115d ago |
| CVE-2026-35299 | 8.8 | — | — | — | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | 115d ago |
| CVE-2026-35267 | 8.8 | — | — | — | oracle / identity manager | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: REST WebServices). | 115d ago |
| CVE-2026-35265 | 8.8 | — | — | — | oracle / identity manager | Vulnerability in the Identity Manager product of Oracle Fusion Middleware (component: Security). | 115d ago |
| CVE-2026-35259 | 8.8 | — | — | — | oracle / weblogic server | Vulnerability in the WebLogic Server product of Oracle Fusion Middleware (component: Console). | 115d ago |
| CVE-2026-0164 | 8.8 | — | — | — | google / android | In Modem, there is a possible out of bounds write due to a missing bounds check. | 116d ago |
| CVE-2026-0162 | 8.8 | — | — | — | google / android | In ParsePayloads of AudioSdpParser.cpp, there is a possible memory corruption due to type confusion. | 116d ago |
| CVE-2026-0161 | 8.8 | — | — | — | google / android | In numberOfReportBlocks of RtpSession.cpp, there is a possible out of bounds write due to an integer overflow. | 116d ago |
| CVE-2026-0160 | 8.8 | — | — | — | google / android | In TextRtpPayloadDecoderNode::DecodeT140 of TextRtpPayloadDecoderNode.cpp, there is a possible out of bounds write | 116d ago |
| CVE-2026-0154 | 8.8 | — | — | — | google / android | In Modem, there is a possible way to trigger a modem crash during a SIP REFER request due to memory corruption. | 116d ago |
| CVE-2026-0151 | 8.8 | — | — | — | google / android | In IntfGraphCreate of intfgraph.c, there is a possible out of bounds write due to an integer overflow. | 116d ago |
| CVE-2026-0149 | 8.8 | — | — | — | google / android | In RtpSession::rtpSendRtcpPacket, there is a possible OOB write due to a heap buffer overflow. | 116d ago |
| CVE-2026-0148 | 8.8 | — | — | — | google / android | In multiple functions of VideoRtpPayloadDecoderNode.cpp, there is a possible out of bounds write due to an integer | 116d ago |
| CVE-2026-0147 | 8.8 | — | — | — | google / android | In __mfc_core_nal_q_get_dec_metadata_sei_nal of mfc_core_nal_q.c, there is a possible out of bounds write due to a | 116d ago |
| CVE-2026-0146 | 8.8 | — | — | — | google / android | In mfc_core_get_dec_metadata_sei_nal of mfc_core_reg_api.c, there is a possible out of bounds write due to a missin | 116d ago |
| CVE-2026-0139 | 8.8 | — | — | — | google / android | In Modem, there is a possible out of bounds write due to a missing bounds check. | 116d ago |
| CVE-2026-0132 | 8.8 | — | — | — | google / android | In Modem, there is a possible out of bounds write due to a heap buffer overflow. | 116d ago |
| CVE-2026-53843 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.26 contains an authorization bypass vulnerability where a surviving pairing-scoped device s | 116d ago |
| CVE-2026-44932 | 8.8 | — | — | — | — | Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by | 116d ago |
| CVE-2024-24909 | 8.8 | — | — | — | — | Dell OpenManage Integration with Microsoft Windows Admin Center contains a Remote Code Execution vulnerability in | 116d ago |
| CVE-2026-12291 | 8.8 | — | — | — | mozilla / firefox | Use-after-free in the Networking: HTTP component. | 116d ago |
| CVE-2026-12289 | 8.8 | — | — | — | mozilla / firefox | Privilege escalation in the Graphics: WebRender component. | 116d ago |
| CVE-2026-5416 | 8.8 | — | — | — | — | Due to the improper neutralization of special elements used in a name parameter a low privileged remote attacker ca | 116d ago |
| CVE-2026-8444 | 8.8 | — | — | — | — | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'curselrevs[]' parameter of th | 116d ago |
| CVE-2026-8443 | 8.8 | — | — | — | — | The WP Review Slider Pro plugin for WordPress is vulnerable to SQL Injection via the 'stypes' and 'slocations' para | 116d ago |
| CVE-2026-6933 | 8.8 | — | — | — | — | The Premmerce Dev Tools plugin for WordPress is vulnerable to Remote Code Execution via missing authorization in ve | 116d ago |
| CVE-2026-7273exploited | 8.8 | 2.5% | 3/3 | +97d | — | A stack-based buffer overflow vulnerability in the CGI program of Zyxel GS1900-48HPv2 firmware versions through 2.9 | 116d ago |
| CVE-2026-12161 | 8.8 | — | — | — | devolutions / remote desktop manager | Improper input validation in the SSH Elevate Shell feature allows an authenticated user with permission to create | 117d ago |
| CVE-2026-48017 | 8.8 | — | — | — | — | DbGate is cross-platform database manager. | 117d ago |
| CVE-2026-49780 | 8.8 | — | — | — | — | Customer Privilege Escalation in Dokan <= 5.0.2 versions. | 117d ago |
| CVE-2026-48889 | 8.8 | — | — | — | — | Subscriber Privilege Escalation in Amelia <= 2.3 versions. | 117d ago |
| CVE-2026-42661 | 8.8 | — | — | — | — | Custom role Path Traversal in WP Customer Area <= 8.3.4 versions. | 117d ago |
| CVE-2026-39579 | 8.8 | — | — | — | — | Contributor Privilege Escalation in B Blocks <= 2.0.31 versions. | 117d ago |
| CVE-2026-39532 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Events Calendar for GeoDirectory <= 2.3.25 versions. | 117d ago |
| CVE-2026-39478 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Anti-Malware Security and Brute-Force Firewall <= 4.23.87 versions. | 117d ago |
| CVE-2026-39474 | 8.8 | — | — | — | — | Contributor PHP Object Injection in Post Duplicator <= 3.0.10 versions. | 117d ago |
| CVE-2026-52720 | 8.8 | — | — | — | — | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). | 117d ago |
| CVE-2026-50884 | 8.8 | — | — | — | — | Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and acces | 117d ago |
| CVE-2026-36670 | 8.8 | — | — | — | — | A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips- | 117d ago |
| CVE-2026-5242 | 8.8 | — | — | — | — | Improper neutralization of formula elements in a CSV file vulnerability in MIA Technology Inc. | 117d ago |
| CVE-2026-49111 | 8.8 | — | — | — | — | Incorrect Privilege Assignment vulnerability in ThemeGrill Masteriyo - LMS allows Privilege Escalation. | 117d ago |
| CVE-2026-49062 | 8.8 | — | — | — | — | Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Engine Faust.Js allows Password Recov | 117d ago |
| CVE-2016-20075 | 8.8 | — | — | — | — | WordPress Ultimate Product Catalog 3.8.6 contains an arbitrary file upload vulnerability that allows authenticated | 117d ago |
| CVE-2026-12192 | 8.8 | — | — | — | — | A vulnerability was determined in GALAYOU Y4 1.0.0. | 118d ago |
| CVE-2026-12187 | 8.8 | — | — | — | — | A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. | 118d ago |
| CVE-2026-12186 | 8.8 | — | — | — | — | A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. | 118d ago |
| CVE-2026-12174 | 8.8 | — | — | — | dlink / dcs-935l firmware | A security vulnerability has been detected in D-Link DCS-935L 1.10.01. | 119d ago |
| CVE-2026-11769 | 8.8 | — | — | — | grafana / grafana operator | We have released version 5.24.0 of the Grafana Operator. | 119d ago |
| CVE-2026-53836 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in PowerShell encoded-command handling that a | 120d ago |
| CVE-2026-53828 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.6 contains an authorization bypass vulnerability in native command handling that allows aut | 120d ago |
| CVE-2026-53822 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 contains a command injection vulnerability where shell wrapper argv could change between | 120d ago |
| CVE-2026-53821 | 8.8 | — | — | — | openclaw / openclaw | OpenClaw before 2026.5.18 accepts WebSocket client-declared operator scopes before binding to server-approved pair | 120d ago |
| CVE-2026-34195 | 8.8 | — | — | — | — | Software installed and run as a non-privileged user may conduct intentional GPU sparse memory API calls to cause o | 120d ago |